At Booth 5300, teams asked Casco to prove it on their software.
They brought us the products. We are scoping the assessments now.
Black Hat USA 2026
Casco has to find a real exploit path inside the agreed scope and return evidence an engineer can act on.

$20K is riding on the result.
The $10,000 RSAC prize went unclaimed. At Black Hat, we doubled it and let each team choose the product.
Challenge prize
$20K
A real target, tested inside agreed scope.
What the challenge measures
Can Casco produce a provable exploit path?
Each assessment starts with agreed scope and follows the attack paths that matter in production. We will publish the outcome after testing is complete.
The prize makes our claim measurable. Casco has to produce a real exploit path and the evidence to prove it.
Five features we launched for Black Hat.
Each one shortens the path from a verified exploit to the fix.
Casco MCP Server
Sends a verified finding into the coding agent, with the evidence attached.
Email Triage
Validates inbound reports against Casco’s exploit standard before they reach the queue.
Automatic Context Refinement Loops
Preserve reviewer decisions across future testing runs.
Slack Bot
Delivers the finding and its evidence to the engineers resolving it.
Network Observability
Ties every Casco request to the corresponding network logs.
The result
One evidence trail from verification through remediation.
Casconaut Highlight
Ian's pick for getting a team out of conference mode.

This issue's Casconaut
Ian Saultz
Cofounder and CTO
Currently recommending
KAMU Ultra Karaoke in Las Vegas
Book a private room and hand the mic to whoever claims they do not sing. Twenty minutes later, nobody is talking about work.
That is my kind of team bonding.
Your turn
Put one production application in front of Casco.
We agree on scope, then Casco runs the assessment against the application. Your engineers receive the exploit path and supporting evidence.